WEBVTT - TechStuff Investigates Operation Ghost Click

0:00:00.320 --> 0:00:02.880
<v Speaker 1>Brought to you by the reinvented two thousand twelve camera.

0:00:03.200 --> 0:00:08.960
<v Speaker 1>It's ready. Are you get in touch with technology? With

0:00:09.039 --> 0:00:17.680
<v Speaker 1>tech Stuff from how stuff looks dot com. Hello again, everyone,

0:00:17.720 --> 0:00:21.799
<v Speaker 1>Welcome to tex Stuff. My name is Chris Polett, and

0:00:21.800 --> 0:00:23.920
<v Speaker 1>I'm an editor at how Stuff works dot com. I'm

0:00:24.000 --> 0:00:26.920
<v Speaker 1>trying to crack up the person sitting across from me,

0:00:27.000 --> 0:00:29.800
<v Speaker 1>and that's the person I usually talked to on these podcasts.

0:00:29.840 --> 0:00:32.600
<v Speaker 1>His name is Jonathan Strickler and and he is a

0:00:32.640 --> 0:00:35.760
<v Speaker 1>senior writer here. To get there, you follow Highway fifty

0:00:35.840 --> 0:00:37.920
<v Speaker 1>eight going northeast out of the city, and it is

0:00:37.960 --> 0:00:42.440
<v Speaker 1>a good highway and New all right, We're we're talking

0:00:42.479 --> 0:00:45.360
<v Speaker 1>about numbers today, Yes we are. We're talking about getting

0:00:45.400 --> 0:00:49.160
<v Speaker 1>to where you're going and getting diverted along the way. So,

0:00:49.880 --> 0:00:51.800
<v Speaker 1>as of the recording of this podcast, which is in

0:00:51.960 --> 0:00:56.080
<v Speaker 1>April of there is a story that's actually not a

0:00:56.080 --> 0:00:59.720
<v Speaker 1>news story necessarily. It first started to kind of make

0:00:59.720 --> 0:01:03.240
<v Speaker 1>the New is way back in November, but it's kind

0:01:03.280 --> 0:01:06.640
<v Speaker 1>of sort of bubbled up and it's an operation that

0:01:06.720 --> 0:01:10.520
<v Speaker 1>the FBI, the Federal Bureau of Investigations, has headed up

0:01:10.959 --> 0:01:16.280
<v Speaker 1>and it all involves hacking into the Internet and uh,

0:01:16.360 --> 0:01:21.320
<v Speaker 1>and and messing around with Internet traffic. It's called Operation

0:01:22.200 --> 0:01:26.880
<v Speaker 1>Ghost Click. That's a nice name. I always love hearing

0:01:26.920 --> 0:01:32.280
<v Speaker 1>the operation names. It is a wacky doctors game. So um,

0:01:32.319 --> 0:01:34.720
<v Speaker 1>I think first, before we get into too much detail,

0:01:34.760 --> 0:01:37.959
<v Speaker 1>we should probably talk about how internet traffic works. We've

0:01:37.959 --> 0:01:41.560
<v Speaker 1>mentioned that on the podcast on a handful of occasions.

0:01:41.600 --> 0:01:43.880
<v Speaker 1>I think when in fact we got into the domain

0:01:44.000 --> 0:01:48.920
<v Speaker 1>name system DNS system or sorry that was redundant, the

0:01:49.000 --> 0:01:52.400
<v Speaker 1>d N s uh no was servers um Well are

0:01:52.440 --> 0:01:55.440
<v Speaker 1>both because DNS can can mean both, but right, right, right,

0:01:55.640 --> 0:01:58.279
<v Speaker 1>So yeah, we talked about it before. And basically every

0:01:58.320 --> 0:02:04.200
<v Speaker 1>website has a is um as an address, a physical address,

0:02:04.280 --> 0:02:07.600
<v Speaker 1>well physical address on on a hard drive, a physical

0:02:07.640 --> 0:02:10.800
<v Speaker 1>hard drive somewhere, and these numbers, there are are four

0:02:10.840 --> 0:02:14.960
<v Speaker 1>sets of numbers separated by periods, and that address is

0:02:15.080 --> 0:02:20.560
<v Speaker 1>unique to that um space on that physical hard drive somewhere.

0:02:20.639 --> 0:02:23.560
<v Speaker 1>And so if you typed in UM h T T

0:02:23.680 --> 0:02:27.000
<v Speaker 1>P colon slash slash and these this number, you will

0:02:27.040 --> 0:02:29.960
<v Speaker 1>get to a website. Of course, that's very inconvenient because

0:02:30.000 --> 0:02:31.880
<v Speaker 1>then you either have to write down these numbers or

0:02:31.880 --> 0:02:34.720
<v Speaker 1>bookmark them or you know, yeah, you have to have

0:02:34.800 --> 0:02:38.760
<v Speaker 1>some sort of weird total recall thing going on where

0:02:38.800 --> 0:02:43.600
<v Speaker 1>you can just easily remember any series of numbers, which would,

0:02:43.680 --> 0:02:49.440
<v Speaker 1>uh would would make you incredibly useful, but it would

0:02:49.440 --> 0:02:51.160
<v Speaker 1>also make you very rare. Most of us, most of

0:02:51.240 --> 0:02:55.040
<v Speaker 1>us are just not It's not something humans are particularly

0:02:55.080 --> 0:02:58.720
<v Speaker 1>good at doing on average. So that is what kind

0:02:58.760 --> 0:03:01.200
<v Speaker 1>of gave rise to the idea of having this domain

0:03:01.360 --> 0:03:04.600
<v Speaker 1>name system. Yes, now, domain name system, what it does

0:03:04.800 --> 0:03:08.639
<v Speaker 1>is it allows you to create a domain name as

0:03:08.680 --> 0:03:13.600
<v Speaker 1>in words that correspond to whatever your site is, and

0:03:13.639 --> 0:03:17.720
<v Speaker 1>then that itself is mapped to this series of numbers,

0:03:17.720 --> 0:03:22.160
<v Speaker 1>this i P address right, the i P being Internet

0:03:22.240 --> 0:03:26.240
<v Speaker 1>protocols UM, which is the the language that gets uh,

0:03:26.480 --> 0:03:29.000
<v Speaker 1>you know, you from one place to another on the Internet,

0:03:29.040 --> 0:03:31.840
<v Speaker 1>regardless of whether you're using a Windows machine, Mac or

0:03:31.880 --> 0:03:35.200
<v Speaker 1>Linux or mobile thing. It gets you to the same place.

0:03:35.240 --> 0:03:37.960
<v Speaker 1>And what allows you to type in how stuff works

0:03:38.000 --> 0:03:41.320
<v Speaker 1>dot com and get to our website. Yes, so if

0:03:41.320 --> 0:03:43.600
<v Speaker 1>you were to type how stuff works dot com, what

0:03:43.720 --> 0:03:47.360
<v Speaker 1>happens is that request you know, what you're essentially doing

0:03:47.400 --> 0:03:49.640
<v Speaker 1>is you're telling your browser I want access to this

0:03:49.720 --> 0:03:54.800
<v Speaker 1>particular website. Your browser sends this message along up a

0:03:54.920 --> 0:03:58.640
<v Speaker 1>chain of command, and uh, you know, it has to

0:03:58.680 --> 0:04:02.440
<v Speaker 1>go out to the right computer that has the website

0:04:02.600 --> 0:04:05.880
<v Speaker 1>living on it and retrieve that so that you get

0:04:05.920 --> 0:04:09.400
<v Speaker 1>an instance of it back at your machine. In order

0:04:09.440 --> 0:04:12.920
<v Speaker 1>to do that, it has to first map that what

0:04:13.040 --> 0:04:14.960
<v Speaker 1>needs to have is the name that you're typing. It

0:04:15.000 --> 0:04:19.840
<v Speaker 1>has to be mapped to that physical machine, that physical drive, uh,

0:04:20.120 --> 0:04:23.080
<v Speaker 1>and it does this by going through domain name servers.

0:04:23.400 --> 0:04:25.800
<v Speaker 1>A domain name server is essentially like think of it

0:04:25.920 --> 0:04:29.480
<v Speaker 1>kind of like a phone book. Yeah, so that all

0:04:29.560 --> 0:04:31.600
<v Speaker 1>the different u r l s you could type in

0:04:32.240 --> 0:04:38.599
<v Speaker 1>are indexed against these number numerical addresses. And then that way,

0:04:38.680 --> 0:04:41.000
<v Speaker 1>once you type in the u r L, it looks

0:04:41.040 --> 0:04:46.320
<v Speaker 1>for the corresponding numeric address, pulls information from that that

0:04:46.360 --> 0:04:50.719
<v Speaker 1>particular source, and then serves it back to you so

0:04:50.800 --> 0:04:54.000
<v Speaker 1>that you get what you asked for. Well that you

0:04:54.120 --> 0:04:59.200
<v Speaker 1>asked for it, you got it anyway. So, um, the

0:04:59.760 --> 0:05:02.720
<v Speaker 1>whole deal here is that you are going to get

0:05:02.960 --> 0:05:07.680
<v Speaker 1>the right information assuming that everything's working correctly, and occasionally

0:05:07.720 --> 0:05:10.960
<v Speaker 1>stuff messes up. There might be uh the computer that

0:05:11.000 --> 0:05:13.720
<v Speaker 1>hosts the site might be down, in which case you're

0:05:13.720 --> 0:05:15.599
<v Speaker 1>going to get something like a four or four error

0:05:16.320 --> 0:05:19.440
<v Speaker 1>because the Internet is not going to be able to

0:05:19.480 --> 0:05:22.520
<v Speaker 1>find the file that you've requested. Very sorry, the Internet

0:05:22.600 --> 0:05:25.760
<v Speaker 1>is broken. The elders of the Internet called and they said,

0:05:25.920 --> 0:05:29.839
<v Speaker 1>no more Internet for you. But most of the time

0:05:30.040 --> 0:05:33.760
<v Speaker 1>it's gonna work just fine. However, what happened in the

0:05:33.839 --> 0:05:38.120
<v Speaker 1>case of Operation ghost Click is that, uh, the FBI

0:05:38.240 --> 0:05:43.839
<v Speaker 1>discovered there were some people who had created some rogue

0:05:43.960 --> 0:05:48.200
<v Speaker 1>DNS servers. So, in other words, these get these folks,

0:05:48.560 --> 0:05:53.680
<v Speaker 1>six Estonian nationals, according to the FBI, um got together

0:05:54.320 --> 0:05:58.279
<v Speaker 1>and created these servers that acted just as a domain

0:05:58.360 --> 0:06:01.520
<v Speaker 1>named server would. So in other words, it had a

0:06:01.600 --> 0:06:03.760
<v Speaker 1>collection of u r l s and index of u

0:06:03.839 --> 0:06:08.360
<v Speaker 1>r l s and an index of addresses numeric addresses.

0:06:08.440 --> 0:06:11.280
<v Speaker 1>So it's like a fake phone book, right exactly. Some

0:06:11.440 --> 0:06:14.919
<v Speaker 1>of the entries in this fake phone book went to

0:06:15.240 --> 0:06:20.040
<v Speaker 1>different phone numbers, so instead literally, yeah, but we're since

0:06:20.080 --> 0:06:23.120
<v Speaker 1>we're sticking with the analogy, sticking with that analogy. So

0:06:23.240 --> 0:06:27.200
<v Speaker 1>instead of the official phone number for a particular website,

0:06:27.200 --> 0:06:29.560
<v Speaker 1>you would get a fake one, and it would, in

0:06:29.600 --> 0:06:31.880
<v Speaker 1>other words, that you would go to a fake numeric

0:06:31.920 --> 0:06:35.000
<v Speaker 1>address for a real site, so you might type in

0:06:35.080 --> 0:06:39.240
<v Speaker 1>the address perfect in your u r L bar. Right,

0:06:39.560 --> 0:06:43.200
<v Speaker 1>So let's take a random example let's just say Yahoo.

0:06:43.760 --> 0:06:48.000
<v Speaker 1>So you do www dot Yahoo dot com, you hit enter. Now, normally,

0:06:48.200 --> 0:06:50.760
<v Speaker 1>in a regular DNS server, it would look up that

0:06:50.920 --> 0:06:54.599
<v Speaker 1>you are L, look to see what the numeric address

0:06:54.720 --> 0:06:57.200
<v Speaker 1>is for that u r L, send that information out,

0:06:57.279 --> 0:07:00.159
<v Speaker 1>retrieve the website, and serve it up to you. A

0:07:00.279 --> 0:07:03.240
<v Speaker 1>rogue DNS server would look up that u r L,

0:07:04.160 --> 0:07:07.599
<v Speaker 1>look at the numeric address that was created for that

0:07:07.760 --> 0:07:10.640
<v Speaker 1>u r L. But it isn't actually the address for Yahoo.

0:07:10.640 --> 0:07:14.040
<v Speaker 1>It's an address for something else, and it serves that

0:07:14.240 --> 0:07:17.480
<v Speaker 1>up to you. Now, why would anyone do this? There

0:07:17.480 --> 0:07:19.480
<v Speaker 1>are a couple of different reasons. Now, in the case

0:07:19.560 --> 0:07:23.280
<v Speaker 1>of the Estonians and uh, they were doing something I

0:07:23.360 --> 0:07:28.320
<v Speaker 1>think that was kind of uh deediously clever. They were

0:07:28.360 --> 0:07:32.720
<v Speaker 1>doing this in order to reroute traffic to break in

0:07:33.040 --> 0:07:36.400
<v Speaker 1>advertising money. So, in other words, what they wanted to

0:07:36.440 --> 0:07:39.880
<v Speaker 1>do was the way advertising on the internetworks in general

0:07:40.000 --> 0:07:42.440
<v Speaker 1>is that you get paid for a certain number of

0:07:42.560 --> 0:07:46.120
<v Speaker 1>views of that ad It's called impressions. The number of

0:07:46.160 --> 0:07:50.360
<v Speaker 1>impressions and ad gets that translates to money, And if

0:07:50.400 --> 0:07:52.720
<v Speaker 1>you get lots and lots and lots of impressions, you

0:07:52.760 --> 0:07:55.720
<v Speaker 1>get lots of money. Um. Then in general, a single

0:07:55.720 --> 0:07:59.320
<v Speaker 1>impression is worth a fraction of assent. Yeah, but if

0:07:59.320 --> 0:08:01.720
<v Speaker 1>you can say, hey, you know, I can promise you

0:08:02.080 --> 0:08:04.800
<v Speaker 1>that five million people are going to see your ad,

0:08:04.960 --> 0:08:09.400
<v Speaker 1>then you can command a good price for your services. Right, So,

0:08:09.560 --> 0:08:13.960
<v Speaker 1>very popular websites can tend to charge more than sites

0:08:14.040 --> 0:08:16.720
<v Speaker 1>that don't get a lot of traffic. Makes sense, Right,

0:08:17.080 --> 0:08:18.920
<v Speaker 1>Let's say that you have a billboard next to a

0:08:18.920 --> 0:08:23.239
<v Speaker 1>busy highway. That the price for that billboard to to

0:08:23.240 --> 0:08:25.000
<v Speaker 1>to put it out on that billboard, it's probably gonna

0:08:25.000 --> 0:08:27.520
<v Speaker 1>be higher than a billboard that's next to a rural

0:08:27.640 --> 0:08:30.640
<v Speaker 1>road that doesn't get a lot of traffic. So anyway,

0:08:30.720 --> 0:08:33.360
<v Speaker 1>the same sort of logic applies on on the web.

0:08:33.960 --> 0:08:36.680
<v Speaker 1>So what these guys were doing, I say, guys, what

0:08:36.800 --> 0:08:39.680
<v Speaker 1>these Estonians were doing because I don't know their gender, Uh,

0:08:39.720 --> 0:08:42.760
<v Speaker 1>they were they were using these rogue DNS servers to

0:08:42.880 --> 0:08:47.240
<v Speaker 1>reroute traffic to go to different websites and that had

0:08:47.320 --> 0:08:51.240
<v Speaker 1>specific ads on them that the Estonians were administering, and

0:08:51.240 --> 0:08:52.880
<v Speaker 1>then they were pulling in the money. So they were

0:08:53.320 --> 0:08:57.440
<v Speaker 1>redirecting traffic. It's like putting in a detour in your route,

0:08:57.800 --> 0:09:00.120
<v Speaker 1>and so you're going down your normal route to to

0:09:00.120 --> 0:09:02.760
<v Speaker 1>wherever you're going, and you see a sign and says, oh, nope,

0:09:02.760 --> 0:09:05.280
<v Speaker 1>the road is out up ahead, take a right instead

0:09:05.280 --> 0:09:08.320
<v Speaker 1>of going straight, and you will go through a different route.

0:09:08.520 --> 0:09:10.800
<v Speaker 1>And along that route you decided to stop and eat.

0:09:11.000 --> 0:09:13.200
<v Speaker 1>And normally you would stop and eat at your favorite restaurant,

0:09:13.200 --> 0:09:14.880
<v Speaker 1>but you can't get to that one because it's on

0:09:14.920 --> 0:09:16.880
<v Speaker 1>the road that's been closed. So you go to this

0:09:16.920 --> 0:09:19.480
<v Speaker 1>other restaurant and it all turns out that it was

0:09:19.520 --> 0:09:21.920
<v Speaker 1>employed by the other restaurant in the first place. They

0:09:21.920 --> 0:09:24.679
<v Speaker 1>put that detour sign up because they wanted to get

0:09:24.800 --> 0:09:27.880
<v Speaker 1>some more foot traffic or some more some more diners

0:09:28.080 --> 0:09:31.800
<v Speaker 1>to come in. That was the general plan. Now the

0:09:31.880 --> 0:09:35.959
<v Speaker 1>question is how do you get that rogue DNS server

0:09:36.400 --> 0:09:39.160
<v Speaker 1>to get in the line of traffic so that people

0:09:39.200 --> 0:09:41.560
<v Speaker 1>will visit it in the first place. Yeah, because if

0:09:41.559 --> 0:09:44.640
<v Speaker 1>you're typing in an address that you already know, say

0:09:44.679 --> 0:09:48.720
<v Speaker 1>Discovery dot com, you should theoretically be routed to the

0:09:48.800 --> 0:09:51.160
<v Speaker 1>right place as long as your computer is configured correctly

0:09:51.559 --> 0:09:53.440
<v Speaker 1>and the internet's working the way it's supposed to. I mean,

0:09:53.440 --> 0:09:54.960
<v Speaker 1>what are they gonna do. Are they gonna go in

0:09:55.120 --> 0:09:59.840
<v Speaker 1>and kick out the legitimate DNS machine and replace it. No,

0:10:00.559 --> 0:10:03.760
<v Speaker 1>it was very clever. They created a kind of malware,

0:10:04.480 --> 0:10:07.520
<v Speaker 1>and the malware is essentially called d n s changer,

0:10:08.400 --> 0:10:12.680
<v Speaker 1>and so DNS changer would change the DNS settings on

0:10:12.880 --> 0:10:16.520
<v Speaker 1>your computer or other device, or even router, which was

0:10:17.160 --> 0:10:20.439
<v Speaker 1>particularly nasty because if it changed on the router, then

0:10:20.520 --> 0:10:23.920
<v Speaker 1>any device that connects through that router would be affected. Also,

0:10:24.679 --> 0:10:27.719
<v Speaker 1>it's unlikely that you're going to have anti virus software

0:10:28.160 --> 0:10:31.240
<v Speaker 1>on your router, although you might on your computer now.

0:10:31.360 --> 0:10:33.120
<v Speaker 1>The way that they did this with the router was

0:10:33.160 --> 0:10:36.360
<v Speaker 1>the easiest way, and it's the easiest way for someone

0:10:36.360 --> 0:10:38.800
<v Speaker 1>to prevent it from happening to them. The way that

0:10:38.880 --> 0:10:41.240
<v Speaker 1>worked on the router was that they just ended up

0:10:41.360 --> 0:10:45.080
<v Speaker 1>using a list of generic user names and passwords that

0:10:45.120 --> 0:10:51.040
<v Speaker 1>are that tend to be UMU administered over various routers.

0:10:51.080 --> 0:10:54.600
<v Speaker 1>So you pick pick a router, like whatever router you

0:10:54.600 --> 0:10:57.920
<v Speaker 1>you happen to use, that router tends to have a

0:10:57.960 --> 0:11:01.120
<v Speaker 1>standard user name and standard password you are supposed to

0:11:01.200 --> 0:11:04.560
<v Speaker 1>change once you install it into your home network, but

0:11:04.640 --> 0:11:07.400
<v Speaker 1>a lot of people never get around to doing that.

0:11:07.800 --> 0:11:11.640
<v Speaker 1>They install the the the router and then they don't

0:11:11.679 --> 0:11:14.120
<v Speaker 1>bother changing the user name and password, which means that

0:11:14.200 --> 0:11:18.000
<v Speaker 1>anyone who knows what the standard user name and password

0:11:18.040 --> 0:11:20.680
<v Speaker 1>is for that brand of router could get access to

0:11:20.720 --> 0:11:23.720
<v Speaker 1>that network. That's what they were doing in this case.

0:11:23.920 --> 0:11:27.240
<v Speaker 1>But in order to change the computers themselves, not the router,

0:11:27.600 --> 0:11:30.160
<v Speaker 1>what they had to do was convince people to download

0:11:30.240 --> 0:11:34.720
<v Speaker 1>some malware and execute that. Now social engineering, Yeah, lots

0:11:34.760 --> 0:11:36.920
<v Speaker 1>of different ways of doing that. Yeah, you know, there's

0:11:36.960 --> 0:11:41.760
<v Speaker 1>the very standard way where they include some uh they

0:11:41.840 --> 0:11:44.400
<v Speaker 1>put on on a website that you might encounter a

0:11:44.440 --> 0:11:48.120
<v Speaker 1>little pop up that says, hey, you're anti virus software

0:11:48.160 --> 0:11:50.280
<v Speaker 1>is out of date. Install this and we will scan

0:11:50.400 --> 0:11:54.400
<v Speaker 1>your computer for viruses and free, yeah, for free. And

0:11:54.440 --> 0:11:58.120
<v Speaker 1>in fact it really is a virus itself that installs

0:11:58.120 --> 0:12:00.200
<v Speaker 1>to your computer. You know, you think you are trying

0:12:00.280 --> 0:12:03.400
<v Speaker 1>to head off some sort of malware and in fact

0:12:03.440 --> 0:12:06.240
<v Speaker 1>you're actually installing malware to your computer at the time.

0:12:07.160 --> 0:12:09.959
<v Speaker 1>Or it could be through email attachments, you know, all

0:12:10.000 --> 0:12:14.360
<v Speaker 1>the standard ways that malware propagates across the web, any

0:12:14.400 --> 0:12:16.920
<v Speaker 1>of that would work to get this this particular kind

0:12:16.920 --> 0:12:20.640
<v Speaker 1>of malware onto your machine. Once you installed it, whether

0:12:20.679 --> 0:12:24.079
<v Speaker 1>it was through a trojan program or whatever, it would

0:12:24.080 --> 0:12:28.560
<v Speaker 1>go and reset the DNS settings on your computer, and

0:12:28.679 --> 0:12:31.240
<v Speaker 1>it would direct your computer to go to these rogue

0:12:31.360 --> 0:12:36.480
<v Speaker 1>DNS servers as opposed to your Internet service providers DNS servers,

0:12:36.840 --> 0:12:39.679
<v Speaker 1>because h I SP has its own right that passes

0:12:39.720 --> 0:12:44.079
<v Speaker 1>the information up along the chain of command. So uh,

0:12:44.280 --> 0:12:46.760
<v Speaker 1>you would bypass your I s P S servers. You

0:12:46.760 --> 0:12:48.760
<v Speaker 1>would go to these rogue servers, and then you would

0:12:48.760 --> 0:12:52.240
<v Speaker 1>be directed to whatever website they wanted to direct YouTube

0:12:52.280 --> 0:12:54.800
<v Speaker 1>for any particular u r L. For some u r

0:12:54.960 --> 0:12:57.199
<v Speaker 1>l s, you might just get the regular website you

0:12:57.440 --> 0:13:01.199
<v Speaker 1>you're sent along and nothing bad happen. For other u

0:13:01.320 --> 0:13:03.440
<v Speaker 1>r l s, you might be directed to a site

0:13:03.480 --> 0:13:05.920
<v Speaker 1>that looks very similar to the one you wanted, but

0:13:06.160 --> 0:13:08.959
<v Speaker 1>something isn't quite right, and it tends that again, they

0:13:08.960 --> 0:13:11.320
<v Speaker 1>were just doing it for the advertising money. The scary

0:13:11.360 --> 0:13:13.600
<v Speaker 1>thing is they could have done this for any other

0:13:13.679 --> 0:13:17.640
<v Speaker 1>reason and actually tried to steal stuff directly from the user.

0:13:18.559 --> 0:13:20.800
<v Speaker 1>Now in this case, that doesn't seem to be what

0:13:20.880 --> 0:13:23.760
<v Speaker 1>they were up to. They were up to just redirecting

0:13:23.760 --> 0:13:27.240
<v Speaker 1>that traffic. So you might think, well, that's annoying. I mean,

0:13:27.280 --> 0:13:28.800
<v Speaker 1>I'm not going to get to the website I want

0:13:28.800 --> 0:13:31.840
<v Speaker 1>to go to unless I type in the actual uh,

0:13:31.960 --> 0:13:36.040
<v Speaker 1>numeric address physically, then I would go to it. But UH,

0:13:36.240 --> 0:13:37.960
<v Speaker 1>while it's annoying that I wouldn't go to the site

0:13:37.960 --> 0:13:39.400
<v Speaker 1>that I wanted to go to, at least they're not

0:13:39.440 --> 0:13:42.360
<v Speaker 1>stealing from me. But they could have. They could have

0:13:42.440 --> 0:13:45.400
<v Speaker 1>directed things so that you would go to dummy websites

0:13:45.440 --> 0:13:49.480
<v Speaker 1>that look similar to official ones and put in a

0:13:49.559 --> 0:13:51.840
<v Speaker 1>system where you type in your user name and password

0:13:52.120 --> 0:13:54.640
<v Speaker 1>and they would log it. They could have logged it,

0:13:54.679 --> 0:13:57.839
<v Speaker 1>they didn't. They could have logged that information, thus getting

0:13:57.880 --> 0:14:00.600
<v Speaker 1>access to various accounts across the net. They could have

0:14:00.600 --> 0:14:04.480
<v Speaker 1>gotten access to email accounts, bank accounts, you know, any

0:14:04.520 --> 0:14:08.600
<v Speaker 1>other sort of anything that would require authorization. They could

0:14:08.679 --> 0:14:12.240
<v Speaker 1>have done that. Uh, And what would probably have happened

0:14:12.240 --> 0:14:13.680
<v Speaker 1>is that you would have logged in. Let's say that

0:14:13.720 --> 0:14:17.040
<v Speaker 1>you try to go to your banks online banking site,

0:14:17.640 --> 0:14:19.920
<v Speaker 1>and you might get a site that looks very much

0:14:20.160 --> 0:14:22.920
<v Speaker 1>like your banks site. In fact, it might even look

0:14:22.960 --> 0:14:26.440
<v Speaker 1>almost identical. Um, the address might look a little hinky,

0:14:26.880 --> 0:14:28.440
<v Speaker 1>but if you were to type an years the name

0:14:28.440 --> 0:14:31.320
<v Speaker 1>and password, likely you would get a response saying, oh,

0:14:31.640 --> 0:14:35.560
<v Speaker 1>sites down for maintenance. But what's really happened is that

0:14:35.560 --> 0:14:38.080
<v Speaker 1>that information has been logged by hackers, so that could

0:14:38.160 --> 0:14:41.560
<v Speaker 1>have happened, or they could have directed you to a

0:14:41.680 --> 0:14:44.720
<v Speaker 1>site where you would have been encouraged to download even

0:14:44.760 --> 0:14:49.240
<v Speaker 1>more malware, perhaps a back door access programs that you

0:14:49.320 --> 0:14:51.280
<v Speaker 1>are your computer would become part of a bot net

0:14:51.720 --> 0:14:56.880
<v Speaker 1>or any other kind of of hacking tool. It's it's

0:14:57.000 --> 0:14:59.680
<v Speaker 1>really the options are pretty much unlimited. Now. In this case,

0:14:59.720 --> 0:15:02.040
<v Speaker 1>again it was just to redirect traffic. However, there were

0:15:02.080 --> 0:15:07.360
<v Speaker 1>some other problems that would happen if you were affected

0:15:07.360 --> 0:15:10.200
<v Speaker 1>by this virus. You might not you know, you might

0:15:10.240 --> 0:15:13.000
<v Speaker 1>not have anyone stealing from your bank account or anything.

0:15:13.200 --> 0:15:15.560
<v Speaker 1>But one of the things the virus does, which is

0:15:15.600 --> 0:15:19.640
<v Speaker 1>pretty much standard operating procedure for viruses, is it turned

0:15:19.760 --> 0:15:23.320
<v Speaker 1>off the features on your operating system and your anti

0:15:23.360 --> 0:15:28.080
<v Speaker 1>virus from updating, so that you wouldn't be able to

0:15:28.120 --> 0:15:31.480
<v Speaker 1>get the latest security patches that would prevent this this

0:15:31.680 --> 0:15:36.400
<v Speaker 1>UH program from working. So first step pretty much of

0:15:36.440 --> 0:15:39.640
<v Speaker 1>any malware is let's disable the stuff that can turn

0:15:40.000 --> 0:15:44.960
<v Speaker 1>this off. So anything that would automatically turn the malware

0:15:44.960 --> 0:15:47.960
<v Speaker 1>off was disabled. So that's a problem because it means

0:15:48.000 --> 0:15:53.360
<v Speaker 1>that even if you aren't being actively preyed upon by

0:15:53.520 --> 0:15:58.120
<v Speaker 1>these particular hackers, uh, future attacks could hit you much

0:15:58.120 --> 0:16:00.840
<v Speaker 1>more easily because you are no longer protected it, yeah,

0:16:01.200 --> 0:16:03.680
<v Speaker 1>which is pretty bad. That's what we call a bad

0:16:03.720 --> 0:16:07.000
<v Speaker 1>thing and internet security. And they were about what four

0:16:07.040 --> 0:16:10.440
<v Speaker 1>million people around the world and about a hundred countries

0:16:10.800 --> 0:16:13.280
<v Speaker 1>that were affected by this, and then five thousand in

0:16:13.280 --> 0:16:16.040
<v Speaker 1>the United States. And it wasn't just uh, you know,

0:16:16.160 --> 0:16:20.400
<v Speaker 1>citizen users, it was also businesses, government, government computers. UM.

0:16:20.400 --> 0:16:22.360
<v Speaker 1>I think there were even like a couple of computers

0:16:22.360 --> 0:16:26.280
<v Speaker 1>over at NASA that were affected to and uh. And

0:16:27.120 --> 0:16:29.800
<v Speaker 1>the good news that we have is that the FBI

0:16:30.040 --> 0:16:34.120
<v Speaker 1>arrested these six Estonian nationals that were identified as being

0:16:34.240 --> 0:16:37.240
<v Speaker 1>part of this running actually running this ring. Yeah, they

0:16:37.280 --> 0:16:38.800
<v Speaker 1>were going to try to have them extradited into the

0:16:38.880 --> 0:16:43.080
<v Speaker 1>United States. Yeah. And they've also taken over the rogue

0:16:43.160 --> 0:16:45.880
<v Speaker 1>DNS servers they have identified as being part of this,

0:16:46.560 --> 0:16:50.440
<v Speaker 1>and those rogue DNS servers are now acting like legitimate

0:16:50.520 --> 0:16:53.800
<v Speaker 1>DNS servers, which is great. That means that as a user,

0:16:54.080 --> 0:16:56.240
<v Speaker 1>when you try to visit a website, you should get

0:16:56.280 --> 0:17:00.000
<v Speaker 1>what you're supposed to get. However, there's a problem because

0:17:00.000 --> 0:17:03.600
<v Speaker 1>as your computer is still have if you're affected, your

0:17:03.600 --> 0:17:07.280
<v Speaker 1>computer still is directing you to the wrong set of servers.

0:17:07.359 --> 0:17:10.200
<v Speaker 1>You're still getting the right result, but you're going and

0:17:10.240 --> 0:17:12.800
<v Speaker 1>you're not going to the regular chain of command that

0:17:12.840 --> 0:17:15.240
<v Speaker 1>you should go to. And the FBI is not going

0:17:15.280 --> 0:17:18.800
<v Speaker 1>to be running these servers forever, and in fact, in

0:17:18.800 --> 0:17:23.240
<v Speaker 1>in July, they're going to turn them off. And once

0:17:23.280 --> 0:17:25.800
<v Speaker 1>those turn off, if your computer is being directed to

0:17:25.840 --> 0:17:29.640
<v Speaker 1>those DNS servers, you may not have any more Web access,

0:17:30.400 --> 0:17:33.240
<v Speaker 1>at least not through typing in a normal u r L,

0:17:33.400 --> 0:17:35.520
<v Speaker 1>because your computer is going to try and go through

0:17:35.520 --> 0:17:40.400
<v Speaker 1>a pathway that doesn't exist anymore. So the important thing

0:17:40.400 --> 0:17:44.240
<v Speaker 1>to do is to determine whether or not your computer

0:17:44.680 --> 0:17:47.720
<v Speaker 1>has this infection, and if it does have the infection,

0:17:47.800 --> 0:17:51.480
<v Speaker 1>to clear it up. And uh, it's the first one

0:17:51.560 --> 0:17:54.159
<v Speaker 1>is easier than the second one. Yeah, the FBI actually

0:17:54.200 --> 0:17:58.359
<v Speaker 1>set up a website designed to help you identify whether

0:17:58.440 --> 0:18:01.560
<v Speaker 1>or not you have been affected. Yes, um, you can

0:18:01.600 --> 0:18:04.960
<v Speaker 1>go to the FBI's website and follow the links to

0:18:05.000 --> 0:18:11.480
<v Speaker 1>find out about whether or not your computer has this problem.

0:18:11.560 --> 0:18:14.000
<v Speaker 1>And there's actually a couple different ways of doing it.

0:18:14.080 --> 0:18:16.639
<v Speaker 1>There's they've they've set up a u r L where

0:18:16.680 --> 0:18:18.720
<v Speaker 1>what it does is it pings a server and if

0:18:18.720 --> 0:18:22.160
<v Speaker 1>it gets a positive results saying that you're fine. Uh,

0:18:22.200 --> 0:18:24.240
<v Speaker 1>you get a screen that has this big green icon

0:18:24.320 --> 0:18:27.679
<v Speaker 1>on it and says you're good. Um. If you're not fine,

0:18:27.760 --> 0:18:30.159
<v Speaker 1>you get a big red icon which says this is

0:18:30.200 --> 0:18:32.199
<v Speaker 1>saying that you're you know, it's going through one of

0:18:32.240 --> 0:18:36.560
<v Speaker 1>the rogue DNS servers. They've also identified a range of

0:18:36.600 --> 0:18:41.119
<v Speaker 1>the IP addresses that you know. You can check your

0:18:41.200 --> 0:18:43.600
<v Speaker 1>DNS settings on your computer yourself. If you're using a

0:18:43.640 --> 0:18:46.560
<v Speaker 1>Windows machine, you go to a run command and you

0:18:46.600 --> 0:18:50.359
<v Speaker 1>type an IP configured slash all uh, and then that'll

0:18:50.400 --> 0:18:53.520
<v Speaker 1>pull up your DNS settings and you can see what

0:18:53.760 --> 0:18:57.679
<v Speaker 1>the what the numeric address is for the server that

0:18:57.760 --> 0:18:59.920
<v Speaker 1>you go to, and if it falls within the rain

0:19:00.200 --> 0:19:02.920
<v Speaker 1>that's been identified by the FBI, you know that your

0:19:03.040 --> 0:19:06.919
<v Speaker 1>DNS settings are wrong. Clearing this up and getting rid

0:19:06.960 --> 0:19:09.920
<v Speaker 1>of the malware is a little tricky. Uh. The easiest

0:19:09.960 --> 0:19:11.919
<v Speaker 1>way I can think of to do it, if I

0:19:11.920 --> 0:19:14.320
<v Speaker 1>were doing it myself, is going to a computer that

0:19:14.400 --> 0:19:19.600
<v Speaker 1>I know has not been affected and downloading the latest

0:19:19.640 --> 0:19:23.320
<v Speaker 1>anti virus software I can find and putting Most of

0:19:23.320 --> 0:19:27.000
<v Speaker 1>them have an option where you can put a version

0:19:27.040 --> 0:19:30.800
<v Speaker 1>of that onto a thumb drive. Do that, then take

0:19:30.840 --> 0:19:34.439
<v Speaker 1>the thumb drive over to the infective machine and booted

0:19:34.480 --> 0:19:38.040
<v Speaker 1>into safe mode and load up the antivirus software from

0:19:38.080 --> 0:19:40.960
<v Speaker 1>the thumb drive, and that should be able. Depending upon

0:19:41.640 --> 0:19:43.720
<v Speaker 1>the anti virus software, it should be able to scan

0:19:43.800 --> 0:19:47.399
<v Speaker 1>it and remove it. Um. The FBI also points to

0:19:47.520 --> 0:19:52.400
<v Speaker 1>several web assets that can help you if your computer

0:19:52.880 --> 0:19:54.640
<v Speaker 1>does appear to be one of the ones that infected,

0:19:54.680 --> 0:19:57.320
<v Speaker 1>and those may work very well for you. I tend

0:19:57.400 --> 0:19:59.920
<v Speaker 1>to go with the anti virus approach whenever I can,

0:20:00.000 --> 0:20:04.639
<v Speaker 1>and UM, it just I don't know, I don't know

0:20:04.680 --> 0:20:07.280
<v Speaker 1>it is. I just have a preference for that as

0:20:07.320 --> 0:20:11.640
<v Speaker 1>opposed to going like a web based route. Yea, um,

0:20:11.680 --> 0:20:14.760
<v Speaker 1>but it is. It is fairly easy to uh to

0:20:14.800 --> 0:20:17.000
<v Speaker 1>get rid of the problem in this case. It's not

0:20:17.040 --> 0:20:19.680
<v Speaker 1>like some of the others where you have to UH

0:20:19.720 --> 0:20:23.440
<v Speaker 1>reformat your hard drive to get it back. Yeah, there's

0:20:23.480 --> 0:20:28.080
<v Speaker 1>there's something. Depending on how tech savvy you are, it's

0:20:28.080 --> 0:20:30.880
<v Speaker 1>pretty easy. If you're not terribly tech savvy, it may

0:20:30.920 --> 0:20:32.919
<v Speaker 1>be it may be worth it to take it to

0:20:33.119 --> 0:20:36.480
<v Speaker 1>a computer professional to have them scan it and remove

0:20:36.520 --> 0:20:39.240
<v Speaker 1>it and take care of it for you, because the

0:20:39.280 --> 0:20:42.000
<v Speaker 1>more you mess with your computer settings, the more you

0:20:42.200 --> 0:20:48.280
<v Speaker 1>may inadvertently cause some problems that can turn your machine

0:20:48.359 --> 0:20:52.439
<v Speaker 1>into a nightmare. Um. And and sometimes depending on the malware,

0:20:52.520 --> 0:20:54.639
<v Speaker 1>like if you've had this on your computer for a while,

0:20:55.200 --> 0:20:57.600
<v Speaker 1>that might not be the only malware that's affecting you.

0:20:58.359 --> 0:21:01.359
<v Speaker 1>You might have other problems, in which case, uh, you know,

0:21:01.400 --> 0:21:05.040
<v Speaker 1>a simple scan and remove may not be enough. In

0:21:05.080 --> 0:21:07.919
<v Speaker 1>a worst case scenario, you might have to do something

0:21:07.960 --> 0:21:11.280
<v Speaker 1>like wipe your computer and reinstall the uprating system, in

0:21:11.280 --> 0:21:12.919
<v Speaker 1>which case the first thing you want to do is

0:21:12.960 --> 0:21:15.040
<v Speaker 1>back up as much of your data as you possibly

0:21:15.160 --> 0:21:19.280
<v Speaker 1>can and then you do the wipe. But that even

0:21:19.320 --> 0:21:22.040
<v Speaker 1>that is I mean, that's that's like a worst case

0:21:22.080 --> 0:21:26.280
<v Speaker 1>scenario type of thing, and hopefully none of our listeners

0:21:26.320 --> 0:21:27.760
<v Speaker 1>are in that. Well. First of all, hopefully none of

0:21:27.800 --> 0:21:30.560
<v Speaker 1>our listeners have been affected by this malware. But if

0:21:30.600 --> 0:21:33.040
<v Speaker 1>they have, hopefully it's not so severe that and they

0:21:33.080 --> 0:21:37.440
<v Speaker 1>don't have other forms of malware that they can't you know, uh,

0:21:37.600 --> 0:21:41.280
<v Speaker 1>take care of it themselves. Yeah. Um. And of course

0:21:41.280 --> 0:21:42.840
<v Speaker 1>it's always a good idea to back up your hard

0:21:42.920 --> 0:21:45.680
<v Speaker 1>drive on a regular basis anyway, just to make sure

0:21:45.760 --> 0:21:48.520
<v Speaker 1>they always back up your hard drive, to to make

0:21:48.560 --> 0:21:51.679
<v Speaker 1>sure that you have a version of your operating system

0:21:52.119 --> 0:21:54.119
<v Speaker 1>uh installed on there that you can go back to

0:21:54.200 --> 0:21:58.040
<v Speaker 1>that you know is not infected at least hopefully. Yeah.

0:21:58.880 --> 0:22:01.159
<v Speaker 1>But that's that's that's pretty impressive. I mean, the FBI

0:22:01.240 --> 0:22:04.560
<v Speaker 1>has really been promoting the fact that they they had

0:22:04.560 --> 0:22:07.760
<v Speaker 1>this success in taking down or apparent success I should say,

0:22:07.800 --> 0:22:11.959
<v Speaker 1>and taking down this uh this ring, this ring, because um,

0:22:12.000 --> 0:22:13.879
<v Speaker 1>you know this is this is pretty significant. They took

0:22:13.920 --> 0:22:19.399
<v Speaker 1>away traffic from uh legitimate websites in addition to making

0:22:19.400 --> 0:22:24.080
<v Speaker 1>money for themselves with the the alternate fake websites. Um.

0:22:24.080 --> 0:22:27.760
<v Speaker 1>And it does expose the fact that most people are

0:22:27.800 --> 0:22:31.359
<v Speaker 1>are you know, still having to uh to think about

0:22:31.359 --> 0:22:34.760
<v Speaker 1>what they do because they they may very well be

0:22:34.840 --> 0:22:37.080
<v Speaker 1>letting somebody in. It could have been a lot worse

0:22:37.080 --> 0:22:41.399
<v Speaker 1>than it was. Yeah, exploiting the DNS system, which again

0:22:41.520 --> 0:22:47.040
<v Speaker 1>I know, redundant at M machine, exploiting that pin number, um,

0:22:47.080 --> 0:22:49.960
<v Speaker 1>it was pretty ingenious, you know. Essentially, it just shows

0:22:50.000 --> 0:22:54.439
<v Speaker 1>that understanding how the Internet works and building this parallel

0:22:54.560 --> 0:23:00.000
<v Speaker 1>system that exploits the way Internet works was very clear.

0:23:00.040 --> 0:23:04.320
<v Speaker 1>Her Now, of course, it's still depended upon user behavior

0:23:04.520 --> 0:23:07.520
<v Speaker 1>to work, because if no one had downloaded the malware,

0:23:07.560 --> 0:23:12.160
<v Speaker 1>if no one had installed the malware, it wouldn't have um,

0:23:12.440 --> 0:23:14.960
<v Speaker 1>nothing would have happened. You would have had these DNS,

0:23:15.040 --> 0:23:18.000
<v Speaker 1>these rogue DNS servers that would be online and would

0:23:18.000 --> 0:23:20.720
<v Speaker 1>be ready to redirect traffic to wherever they wanted it

0:23:20.760 --> 0:23:23.560
<v Speaker 1>to go. But if no one downloaded the malware, the

0:23:23.560 --> 0:23:27.680
<v Speaker 1>traffic would never have been redirected. So really, the other

0:23:27.960 --> 0:23:31.639
<v Speaker 1>lesson to take away from this is just practice good

0:23:31.760 --> 0:23:36.040
<v Speaker 1>Internet security rules of thumb, things like don't open strange

0:23:36.840 --> 0:23:40.840
<v Speaker 1>attachments from you know, in random emails. Make sure you

0:23:40.920 --> 0:23:43.440
<v Speaker 1>ask people if they've sent you an attachment, asked them

0:23:43.440 --> 0:23:45.040
<v Speaker 1>like did you really send this to me? You know,

0:23:45.040 --> 0:23:50.720
<v Speaker 1>because sometimes people their email address gets compromised and they

0:23:50.840 --> 0:23:56.280
<v Speaker 1>randomly start sending out files two people, often in uncharacteristically

0:23:57.280 --> 0:24:00.680
<v Speaker 1>uh worded ways, like you might read and Usage and think,

0:24:01.440 --> 0:24:08.000
<v Speaker 1>either my friend is taking a terrible fall and decided

0:24:08.040 --> 0:24:12.639
<v Speaker 1>to email me immediately afterwards, or is under the influence

0:24:12.800 --> 0:24:17.359
<v Speaker 1>of some powerful alcohol, or you know, it just doesn't

0:24:17.400 --> 0:24:18.840
<v Speaker 1>make any sense, Like you read it and you're like,

0:24:18.880 --> 0:24:22.919
<v Speaker 1>this doesn't sound like Chris. Chris never emails me in

0:24:23.000 --> 0:24:27.240
<v Speaker 1>all caps with lots of letters missing. UM send this

0:24:27.320 --> 0:24:30.560
<v Speaker 1>to everyone you know, UM. Bill Gates will give you

0:24:30.640 --> 0:24:34.440
<v Speaker 1>twenty five cents for every email that you've forward anyway,

0:24:35.200 --> 0:24:38.240
<v Speaker 1>don't don't open those email attachments. Yeah, and you know

0:24:38.280 --> 0:24:41.720
<v Speaker 1>what I've recently realized, Um, every once in a whilehile

0:24:41.880 --> 0:24:44.080
<v Speaker 1>find a story that I want to send to somebody,

0:24:44.520 --> 0:24:47.800
<v Speaker 1>and I've I've realized as I was sending it, I'd say, hey,

0:24:47.920 --> 0:24:50.040
<v Speaker 1>I just saw this, you should check it out. You

0:24:50.080 --> 0:24:52.760
<v Speaker 1>know what? That sounds just like something a spammer would

0:24:52.760 --> 0:24:55.920
<v Speaker 1>writ So I try to make it a little more personally,

0:24:55.960 --> 0:24:58.320
<v Speaker 1>more personal so that the well, for one thing, the

0:24:58.359 --> 0:25:02.160
<v Speaker 1>spam filter will on a lot of these uh services

0:25:02.160 --> 0:25:04.120
<v Speaker 1>will pull it right out of there if you if

0:25:04.160 --> 0:25:07.560
<v Speaker 1>it's something that that minimal, So if it fits that

0:25:07.640 --> 0:25:11.159
<v Speaker 1>pattern of hey I saw this, check it out, and

0:25:11.160 --> 0:25:15.760
<v Speaker 1>then yeah, it can fall into the spam filter pretty easily. Also,

0:25:16.080 --> 0:25:19.400
<v Speaker 1>and it doesn't just go with attachments like I mean,

0:25:19.720 --> 0:25:22.919
<v Speaker 1>or links. Their links, plenty of links are problems. But

0:25:23.080 --> 0:25:26.040
<v Speaker 1>think about like, gosh, I've seen this so many times

0:25:26.040 --> 0:25:30.600
<v Speaker 1>on Facebook, clickjacking on Facebook. So if you've ever gone

0:25:30.840 --> 0:25:33.199
<v Speaker 1>I'm sure most of you have, anyone who's had a

0:25:33.240 --> 0:25:36.600
<v Speaker 1>Facebook account long enough has seen this happen with their friends.

0:25:37.680 --> 0:25:42.919
<v Speaker 1>You'll look and there'll be some video link. You know,

0:25:42.960 --> 0:25:45.520
<v Speaker 1>it'll say it won't be an embedded video, so it's

0:25:45.560 --> 0:25:48.520
<v Speaker 1>not something that plays within Facebook. But you'll see like

0:25:48.560 --> 0:25:51.920
<v Speaker 1>a link to some incredible video and it usually has

0:25:51.960 --> 0:25:54.359
<v Speaker 1>to do with either violence or sex. Those tend to

0:25:54.400 --> 0:25:57.720
<v Speaker 1>be the two big ones. Yeah. Yeah, you go for

0:25:57.800 --> 0:26:01.240
<v Speaker 1>those base instincts that we human have and uh, and

0:26:01.640 --> 0:26:03.560
<v Speaker 1>you get a lot of results, which is kind of

0:26:03.880 --> 0:26:07.639
<v Speaker 1>a sad commentary, but that's a different podcast. Anyway, there's

0:26:07.680 --> 0:26:10.119
<v Speaker 1>a you know, you'll you'll see this link and I

0:26:10.160 --> 0:26:14.080
<v Speaker 1>saw one recently and immediately I was like, my the

0:26:14.080 --> 0:26:15.800
<v Speaker 1>red flag went up. As soon as I saw it.

0:26:15.800 --> 0:26:17.879
<v Speaker 1>First of all, I was like, this doesn't seem like

0:26:17.920 --> 0:26:20.639
<v Speaker 1>the kind of thing this person would have shared, Like

0:26:20.680 --> 0:26:22.520
<v Speaker 1>they might have clicked on a link, but it doesn't

0:26:22.560 --> 0:26:24.720
<v Speaker 1>seem like something they would have themselves shared. And it

0:26:24.800 --> 0:26:28.600
<v Speaker 1>was a supposedly a video about Justin Bieber being stabbed

0:26:28.680 --> 0:26:31.480
<v Speaker 1>at a concert, And as soon as I saw it,

0:26:31.520 --> 0:26:37.639
<v Speaker 1>I thought, Uh, this has click clickjacking written all over it,

0:26:37.640 --> 0:26:40.920
<v Speaker 1>And immediately I went to one of my favorite references

0:26:40.920 --> 0:26:44.360
<v Speaker 1>for this sort of thing, snopes dot com. So Snopes

0:26:44.480 --> 0:26:47.000
<v Speaker 1>is all about urban legends, but they also look at

0:26:47.040 --> 0:26:51.360
<v Speaker 1>things like internet hoaxes and and clickjacking. And I did

0:26:51.400 --> 0:26:53.440
<v Speaker 1>a quick search and sure enough, this is something that's

0:26:53.440 --> 0:26:55.560
<v Speaker 1>been around for a while, and it just it's just

0:26:55.640 --> 0:26:58.359
<v Speaker 1>like a lot of other clickjacking. It has these cycles

0:26:58.400 --> 0:27:02.479
<v Speaker 1>that goes through where you'll have an initial pop up

0:27:02.480 --> 0:27:05.120
<v Speaker 1>of this and then dies down, and then it'll pop

0:27:05.200 --> 0:27:07.800
<v Speaker 1>up again, and I'll do that three or four times. Yeah.

0:27:07.880 --> 0:27:10.600
<v Speaker 1>Current events are often yeah, and I mean it's it's

0:27:10.800 --> 0:27:12.800
<v Speaker 1>you'll find some of these that that have lasted for

0:27:12.920 --> 0:27:16.480
<v Speaker 1>years that basically they don't necessarily have to be about.

0:27:16.560 --> 0:27:20.880
<v Speaker 1>Justin Bieber for example, that maybe the uh, the click

0:27:20.960 --> 0:27:24.800
<v Speaker 1>jack to your Yeah, exactly, or you know, five years

0:27:24.800 --> 0:27:27.400
<v Speaker 1>ago it could have been about for example, Britney Spears. Yeah,

0:27:27.440 --> 0:27:29.880
<v Speaker 1>that would be a very popular one. And Jennifer Aniston

0:27:30.000 --> 0:27:32.680
<v Speaker 1>or somebody somebody that's in the news right that moment. Yeah,

0:27:32.720 --> 0:27:35.040
<v Speaker 1>And it tends to be like or it'll be like

0:27:35.560 --> 0:27:39.879
<v Speaker 1>this this this news anchor had an embarrassing uh moment

0:27:40.000 --> 0:27:42.919
<v Speaker 1>on the news. Click to find out that sort of stuff.

0:27:43.119 --> 0:27:45.960
<v Speaker 1>And what happens is if you do click that, you'll

0:27:46.000 --> 0:27:49.520
<v Speaker 1>get a message that essentially says usually something like, uh,

0:27:49.600 --> 0:27:53.159
<v Speaker 1>your your you need to install this extension or you

0:27:53.200 --> 0:27:55.720
<v Speaker 1>need to install this video player in order to watch

0:27:55.800 --> 0:27:59.720
<v Speaker 1>this video. And if you allow it, then it gets

0:27:59.800 --> 0:28:02.760
<v Speaker 1>at says to things like your Facebook feed and as

0:28:02.760 --> 0:28:07.399
<v Speaker 1>well as possibly other stuff. It may involve other you know,

0:28:07.960 --> 0:28:11.359
<v Speaker 1>kinds of malware, but in general, you've seen see this

0:28:11.480 --> 0:28:15.080
<v Speaker 1>get propagated across Facebook where someone who has fallen from

0:28:15.080 --> 0:28:18.240
<v Speaker 1>the trick agrees to it and then it continues to

0:28:19.160 --> 0:28:21.720
<v Speaker 1>go across Facebook because it starts to use that person's feed.

0:28:22.400 --> 0:28:25.359
<v Speaker 1>So whenever I see one of these, here's what I do, guys.

0:28:25.640 --> 0:28:28.320
<v Speaker 1>I immediately, you know, I see something that that raises

0:28:28.359 --> 0:28:30.800
<v Speaker 1>a red flag like that. First way I do is

0:28:30.840 --> 0:28:35.000
<v Speaker 1>I do a search on Google for whatever the video

0:28:35.600 --> 0:28:39.040
<v Speaker 1>supposedly shows, because nine times out of ten it's just

0:28:39.080 --> 0:28:42.400
<v Speaker 1>completely made up, and you can usually find up. I

0:28:42.440 --> 0:28:44.240
<v Speaker 1>find an article written on it, or it'll be on

0:28:44.320 --> 0:28:47.000
<v Speaker 1>Snopes or something like that where I'll say, you know,

0:28:47.080 --> 0:28:49.880
<v Speaker 1>this new Facebook scam is going around, so watch out

0:28:49.920 --> 0:28:52.840
<v Speaker 1>for it. Once I have confirmed that it's a scam,

0:28:52.880 --> 0:28:55.080
<v Speaker 1>I go back to Facebook and I comment on the

0:28:55.800 --> 0:28:58.800
<v Speaker 1>entry and I say, hey, it looks like this is

0:28:58.880 --> 0:29:02.480
<v Speaker 1>a click jacking attempt. You may want to go and

0:29:02.480 --> 0:29:06.880
<v Speaker 1>and change your Facebook password and delete this post, because

0:29:06.880 --> 0:29:10.040
<v Speaker 1>by deleting the post, you're going to help remove that

0:29:10.040 --> 0:29:13.240
<v Speaker 1>that step for other people to fall victim to that

0:29:13.360 --> 0:29:17.320
<v Speaker 1>same problem. So I do that fairly regularly because I've

0:29:17.320 --> 0:29:19.840
<v Speaker 1>got a lot of friends on Facebook, and this sort

0:29:19.840 --> 0:29:22.480
<v Speaker 1>of thing can happen to anyone. It's uh and and

0:29:22.720 --> 0:29:27.200
<v Speaker 1>it's not necessarily something that's that's sort of either appealing

0:29:27.280 --> 0:29:31.880
<v Speaker 1>to violence or sex. Sometimes it's something that's just interesting

0:29:32.040 --> 0:29:34.880
<v Speaker 1>and it has nothing to do with any of those

0:29:35.000 --> 0:29:40.680
<v Speaker 1>uh uh kind of more base subject matter writing. And also,

0:29:40.880 --> 0:29:43.360
<v Speaker 1>I mean in general, when there's a link in Facebook,

0:29:43.400 --> 0:29:45.800
<v Speaker 1>if it's a link in Facebook, I tend to go

0:29:45.840 --> 0:29:48.880
<v Speaker 1>to Google anyway and try and get to that link

0:29:48.920 --> 0:29:52.000
<v Speaker 1>without going through Facebook, because you never know when it's

0:29:52.000 --> 0:29:55.480
<v Speaker 1>a clickjacking attempt. If it's an embedded video within Facebook,

0:29:55.520 --> 0:29:57.800
<v Speaker 1>like a YouTube video that's been embedded in Facebook something

0:29:57.840 --> 0:30:00.120
<v Speaker 1>like that, I'm all right with that. I'll watch it

0:30:00.200 --> 0:30:03.840
<v Speaker 1>that way. But for links, I tend to go outside

0:30:03.840 --> 0:30:05.240
<v Speaker 1>of Facebook to do it, just to be on the

0:30:05.280 --> 0:30:09.440
<v Speaker 1>safe side, which I'm sure Facebook hates. That's not what

0:30:09.480 --> 0:30:12.800
<v Speaker 1>Facebook wants to hear. But until they want to track you, right,

0:30:12.920 --> 0:30:15.960
<v Speaker 1>until there's better security around that so that I'm not

0:30:16.760 --> 0:30:19.440
<v Speaker 1>throwing caution to the wind and infecting my computer. I

0:30:19.480 --> 0:30:23.600
<v Speaker 1>just I can't justify it. So that's just my own

0:30:23.600 --> 0:30:26.280
<v Speaker 1>personal approach. Guys, I'm sure all of you probably have

0:30:26.360 --> 0:30:28.320
<v Speaker 1>your own sort of way of dealing with this and

0:30:28.440 --> 0:30:31.640
<v Speaker 1>avoiding problems, but it's always something that's good to keep

0:30:31.680 --> 0:30:34.600
<v Speaker 1>in mind. Uh and um. Anyway, So if you, guys,

0:30:34.760 --> 0:30:38.080
<v Speaker 1>suspect that you might have this DNS change your malware

0:30:38.120 --> 0:30:41.360
<v Speaker 1>on your computer, go to the FBI's website. Use their

0:30:41.360 --> 0:30:44.280
<v Speaker 1>tool first of all to see if you get a

0:30:44.320 --> 0:30:47.320
<v Speaker 1>result back. If you don't get a result back, you're

0:30:47.600 --> 0:30:51.520
<v Speaker 1>probably okay, not necessarily okay. You can pull up that

0:30:51.640 --> 0:30:56.760
<v Speaker 1>list of addresses that do map to these rogue servers

0:30:57.200 --> 0:30:59.960
<v Speaker 1>and go through your computer settings and confirm it that way,

0:31:00.920 --> 0:31:07.320
<v Speaker 1>warning rogue servers. So just check your computers, make sure

0:31:07.320 --> 0:31:10.720
<v Speaker 1>you're you're fine, because if you're not fine, then once

0:31:10.760 --> 0:31:13.280
<v Speaker 1>the FBI turns these servers off, you may have some

0:31:13.360 --> 0:31:16.320
<v Speaker 1>problems accessing stuff over the web, and then you're thinking,

0:31:16.480 --> 0:31:19.200
<v Speaker 1>what the heck happened? And the real nasty part about

0:31:19.200 --> 0:31:21.160
<v Speaker 1>not being able to access the web is not being

0:31:21.160 --> 0:31:24.680
<v Speaker 1>able to access Why you can't access the web I've

0:31:24.720 --> 0:31:28.400
<v Speaker 1>had that happen. Apparently, did I not pay my internet bill?

0:31:28.960 --> 0:31:32.480
<v Speaker 1>Is my router down? I don't know how to check

0:31:32.520 --> 0:31:37.520
<v Speaker 1>because I can't look anything up. Yes, I'm that guy anyway.

0:31:37.560 --> 0:31:39.360
<v Speaker 1>So do you have anything else you want to add

0:31:39.400 --> 0:31:42.040
<v Speaker 1>about this? Not really, not really know, So let us

0:31:42.400 --> 0:31:45.680
<v Speaker 1>wrap this up. Guys, if you have any suggestions for

0:31:45.800 --> 0:31:48.640
<v Speaker 1>future topics on tech Stuff podcasts, you can let us

0:31:48.680 --> 0:31:52.240
<v Speaker 1>know through email that addresses tech stuff add discovery dot

0:31:52.320 --> 0:31:55.600
<v Speaker 1>com or you less know on Facebook or Twitter or

0:31:55.640 --> 0:31:59.880
<v Speaker 1>handle us both those social networks. Is text stuff each

0:32:00.160 --> 0:32:02.040
<v Speaker 1>s W and Chris and I will talk to you

0:32:02.120 --> 0:32:06.480
<v Speaker 1>again really soon. For more on this and thousands of

0:32:06.480 --> 0:32:14.760
<v Speaker 1>other topics, visit how stuff Works dot com. Brought to

0:32:14.760 --> 0:32:17.880
<v Speaker 1>you by the reinvented two thousand twelve camera. It's ready,

0:32:18.080 --> 0:32:18.480
<v Speaker 1>are you